CVE-2026-72660

Source
https://cve.org/CVERecord?id=CVE-2026-72660
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72660.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72660
Aliases
Downstream
Published
2026-08-13T19:12:56Z
Modified
2026-09-04T08:06:33Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Uncaught Exception in Kibana Leading to Denial of Service
Details

Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20), in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged access can cause an internal error condition in Kibana by supplying specially crafted data. The resulting error is raised on an execution path so it propagates as an uncaught exception and terminates the Kibana process. Kibana is unavailable to all users until the service is restarted, and the condition can be triggered repeatedly.

Database specific
{
    "cna_assigner": "elastic",
    "cwe_ids": [
        "CWE-248"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72660.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "8.0.0"
                },
                {
                    "last_affected": "8.19.19"
                },
                {
                    "introduced": "9.0.0"
                },
                {
                    "last_affected": "9.3.7"
                },
                {
                    "introduced": "9.4.0"
                },
                {
                    "last_affected": "9.4.4"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/elastic/elasticsearch

Affected ranges

Type
GIT
Repo
https://github.com/elastic/elasticsearch
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "8.0.0"
        },
        {
            "fixed": "8.19.20"
        },
        {
            "introduced": "9.0.0"
        },
        {
            "fixed": "9.3.8"
        },
        {
            "introduced": "9.4.0"
        },
        {
            "fixed": "9.4.5"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

v9.*
v9.4.0
v9.4.1
v9.4.2
v9.4.3
v9.4.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72660.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "115913013950776467682935266167186214290",
            "length": 443
        },
        "id": "CVE-2026-72660-0394a091",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/171dd53e53c29b91f45d2d87857a3f74db48cca5",
        "target": {
            "file": "x-pack/plugin/core/src/main/java/org/elasticsearch/xpack/core/ml/utils/MlIndexAndAlias.java",
            "function": "hasFieldTypedAs"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "283190670438501987514727838726815920477",
                "139872482520600089094968553951135983484",
                "244928736363048457427079246025589015191"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-72660-15fc2a3d",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94",
        "target": {
            "file": "server/src/test/java/org/elasticsearch/search/fetch/subphase/highlight/PlainHighlighterTests.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "81816716326784163141037864156461492390",
                "193457615837810166023961203333335140451",
                "219949312864961936290517385645475595766",
                "193492332273642270123780157420855738475",
                "109134945049513130160940169446777743717",
                "117749742539505017103393899150508650276",
                "327484658846402275517677001025878754632",
                "88277128083084399881468861707085467538",
                "261752105453815012587785041956160391569",
                "45219006148435694893618332155695206738",
                "247400239131959349329922561927948738354",
                "297143970384114240916019390040752528710",
                "219561097176965364021383399693993096195",
                "174756042447011514348682282304277857750",
                "295187533307863769403119595053335806808",
                "127757002294872223858010470453881573595",
                "76127827453759183834786055401076437523",
                "27862674806732483010218336574864014860",
                "139168849936502340267087795027387029590",
                "335161156717404889718272437713634409769",
                "242204158689472787917814084807122224632",
                "228351892385528956460654896704676575935",
                "108930408417477068391252722732201965832"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-72660-2ecb32d4",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/171dd53e53c29b91f45d2d87857a3f74db48cca5",
        "target": {
            "file": "x-pack/plugin/ml/src/test/java/org/elasticsearch/xpack/ml/MlAnomaliesIndexUpdateTests.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "35973537492193988444530376691395407843",
            "length": 2369
        },
        "id": "CVE-2026-72660-3749bff4",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94",
        "target": {
            "file": "server/src/main/java/org/elasticsearch/search/fetch/subphase/highlight/AbstractHighlighterBuilder.java",
            "function": "setupParser"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "291831910690966635218544031672950971478",
                "161152085631897994744104891500764725967",
                "127236844828659388597695288999749917490",
                "261379068811515202666545085705261440192",
                "337682173461037959368100046130311712933",
                "208689412399050376270863926713279996472",
                "233907370603805937211272082051031503525",
                "190417235538415989055244158763197593722"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-72660-4df5c1e0",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/171dd53e53c29b91f45d2d87857a3f74db48cca5",
        "target": {
            "file": "x-pack/qa/rolling-upgrade/src/test/java/org/elasticsearch/upgrades/MlMappingsUpgradeIT.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "114508176030696626539066047296433779214",
                "43384607500169746049581282043376952148",
                "283563727296098110195444588655154165811",
                "277031765205288332698033581440269116720",
                "187407052376657667672985622362187421922",
                "90126549817761157374395826113896432271",
                "62431126033836515299954878706677890458",
                "276372619117036678140958072933552714348",
                "34204804071724460000309539643270206424",
                "178874689487166837173458238589286447776"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-72660-56785d56",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94",
        "target": {
            "file": "server/src/main/java/org/elasticsearch/search/fetch/subphase/highlight/HighlightBuilder.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "130974301542137558840448047842862618269",
                "310384723823813034858297363478666431577"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-72660-5cd5b1b7",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/171dd53e53c29b91f45d2d87857a3f74db48cca5",
        "target": {
            "file": "x-pack/plugin/core/src/test/java/org/elasticsearch/xpack/core/ml/utils/MlIndexAndAliasTests.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "233121128229985219156668576977333876288",
                "322038067866141381526771770641116867245",
                "241430259805230103725201070300611475508",
                "71318714060438215369602882120931554844",
                "19463283512534906609410116339369250684",
                "103496732783466577522595948932409730311",
                "155310668681586578284879423735099690318",
                "63301931713071047032833396515427666185",
                "172640144808196375156343472350222055588",
                "229896768205556589988297775201735715505",
                "47208004096404474157949582568811506150",
                "126854002759364804916266098874108951477",
                "14107338448903472933351885960178041593",
                "66745378341942989349900429020686187568",
                "262821386059642390664811956572796391799",
                "31104652174867756272822497479626521413",
                "151910984870007046939085084370763218351"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-72660-6460fc3c",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/171dd53e53c29b91f45d2d87857a3f74db48cca5",
        "target": {
            "file": "x-pack/plugin/core/src/main/java/org/elasticsearch/xpack/core/ml/utils/MlIndexAndAlias.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "74600334261879604741521313242640339568",
            "length": 4662
        },
        "id": "CVE-2026-72660-687797ed",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94",
        "target": {
            "file": "server/src/main/java/org/elasticsearch/search/fetch/subphase/highlight/PlainHighlighter.java",
            "function": "highlight"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "10160088286724545746756661846724288313",
            "length": 176
        },
        "id": "CVE-2026-72660-6e669937",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94",
        "target": {
            "file": "server/src/test/java/org/elasticsearch/search/fetch/subphase/highlight/HighlightBuilderTests.java",
            "function": "getFieldType"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "101393873990096950420991800416251882918",
                "23490955719992678536167815105830831478",
                "275894198653151692933552380072493919347",
                "202501215400856585332211908356249536154",
                "38093348454503211711412222191970061779",
                "245246626249461445125795220025727028592",
                "180958960369218863836974260262140085967",
                "337350380980350042081781305366538775470",
                "209841966927085880094961636819164294326",
                "161393650047555658935815194508550352145",
                "330517082616902116482067993370942531899",
                "139204962687075029824507759713221564811",
                "23092223225320115423316205456624802397",
                "37420460032820905945586347346833340838",
                "56751750874276172321310225949913672733",
                "139074372557140290886430200439833044447",
                "141385189185576989096725233165411591300",
                "206795474029433025082976745152568547550",
                "198930134595639097471839755328603906939",
                "159807356369538152020721402072228673398",
                "117728750679808310613840053309847667139",
                "172906292808846080081860718130397529035",
                "77382181164524361686824059687819226277",
                "81986912303227812355627883674974956034",
                "245767764611893032166803726880040920216",
                "231099459878349177561531680968163033991",
                "6669464796606121548655461477703233517",
                "135583465348717599625336164574164606818",
                "242389645836035778480535609937826583277",
                "111675281323712967699314260735726811809",
                "165445570640752170002877819503430379486",
                "166261080474479085574148431053135176552",
                "109311873620279040957844750750051860908",
                "246755689251828643152877627567504552117",
                "239899546813507800298746642496596055672",
                "212209778102963534965342299609543145657",
                "282878794880246854237680563971348320616",
                "74624459302890992150581015592478906823",
                "173196531197277496905860757850433510424"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-72660-7d2dcc21",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/171dd53e53c29b91f45d2d87857a3f74db48cca5",
        "target": {
            "file": "x-pack/plugin/ml/src/main/java/org/elasticsearch/xpack/ml/MlAnomaliesIndexUpdate.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "303281486317530552893821687171494518785",
            "length": 1255
        },
        "id": "CVE-2026-72660-83301d6d",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/171dd53e53c29b91f45d2d87857a3f74db48cca5",
        "target": {
            "file": "x-pack/plugin/ml/src/main/java/org/elasticsearch/xpack/ml/MlAnomaliesIndexUpdate.java",
            "function": "healOneBadIndex"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "161461265920098109707747385294147369779",
            "length": 1809
        },
        "id": "CVE-2026-72660-89723ca9",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/171dd53e53c29b91f45d2d87857a3f74db48cca5",
        "target": {
            "file": "x-pack/plugin/ml/src/main/java/org/elasticsearch/xpack/ml/MlAnomaliesIndexUpdate.java",
            "function": "emitAdvisoryNotifications"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "130192812032915568189929366428112074279",
                "338587668112843751875004607897056457244",
                "311636223832287298418351940618914661904",
                "14559433973571236327103093772803942734",
                "81766092491860980139880041074416541030",
                "83778004218823664808743686188872036723",
                "217672029278899031516016760140755058444"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-72660-9734acfc",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94",
        "target": {
            "file": "server/src/main/java/org/elasticsearch/rest/action/search/SearchCapabilities.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "280077327868295105608486500378173092851",
                "43015048598310775409495333102726391169",
                "137751066797260795582560576962541718966",
                "142113089162365310946470839866993266027"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-72660-afcc8302",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/171dd53e53c29b91f45d2d87857a3f74db48cca5",
        "target": {
            "file": "x-pack/plugin/ml/src/main/java/org/elasticsearch/xpack/ml/MlIndexTemplateRegistry.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "243868588130949656791143692081236563864",
                "311505216586199373294314499230294889565",
                "23300629379259170631342652985157100415",
                "99779525804820300359777388439313924719",
                "124392759507223488964887386448798184793",
                "57056074566821104672192600168236166604",
                "183428232184500482658775793061523078930"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-72660-bd63b83e",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94",
        "target": {
            "file": "server/src/main/java/org/elasticsearch/search/fetch/subphase/highlight/AbstractHighlighterBuilder.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "195251013402414028464036428127401944068",
            "length": 757
        },
        "id": "CVE-2026-72660-bebcec38",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/171dd53e53c29b91f45d2d87857a3f74db48cca5",
        "target": {
            "file": "x-pack/qa/rolling-upgrade/src/test/java/org/elasticsearch/upgrades/MlMappingsUpgradeIT.java",
            "function": "testMappingsUpgrade"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "122639132757664986803138175691671001655",
                "335892283999867396276535502941166644649",
                "252845685254806679929754126735709659653",
                "70459544080609156892578956654685198979",
                "288350301639674802567568120843372854348",
                "128879439556083118790804565740578695567",
                "183568503689704087885138164738553210791",
                "315988264130765396628199666193426980549",
                "110105306531665817097053229432225710351",
                "108886619290626151118397149603734671098",
                "68900764452827513161409585113073530589",
                "109699481272201296627752008736891181922",
                "89552474233322494405147063649180198152",
                "243794874480578150177830085733756836217",
                "128936352400535787295390066296206280301",
                "168193967744077208144892951303807415035",
                "32485489507345202777470620624306770167",
                "82468793747458534960176489784612968344",
                "95431536162858288727547312167888083055",
                "79895802567313409968279279144916310561",
                "109983373614664327492018760324106301607",
                "254164139643632659290414288579740637195",
                "218911482828271878345863242741149783938",
                "290149128642774742559654272690374710990",
                "129649976829885946269329561068451864187",
                "271521553609249011929656203339955131993",
                "116967678018103273313850160203491775016",
                "34507466461561024444180968955125864688",
                "149539466270008484339757108260134471872",
                "241540141246676079432554907112288153733",
                "247281622777097759942516432384261889326",
                "8682106367820934505412234917026602498",
                "258599880353756871245323998211345504441",
                "140682565192181975671989624265695960587",
                "100268892565605616091333444189761449681",
                "214950598829781998119271592022997186976",
                "200550104524719405385075838124186899375",
                "313720121068230248463194804287647092807",
                "188167255630204728049901172366742944889",
                "197051329735330186721065881872811534640",
                "246392715163119707808625433035684232434",
                "127945619089996738346525337879859203179",
                "136702270964155933380398036066653195170"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-72660-ca3692e7",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94",
        "target": {
            "file": "server/src/test/java/org/elasticsearch/search/fetch/subphase/highlight/HighlightBuilderTests.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "55892219538835031952319089164074182258",
                "98893125584566396768016509024864438414",
                "19458546747287293758961852067136502121",
                "184762767260389321870124416427883759205",
                "111219214059868615047400935392923393010",
                "45724314446742059907257730571042785532",
                "179713398058643943713754786096284698281"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-72660-cfefdc32",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/171dd53e53c29b91f45d2d87857a3f74db48cca5",
        "target": {
            "file": "x-pack/plugin/ml/src/test/java/org/elasticsearch/xpack/ml/MlIndexTemplateRegistryTests.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "186492591955110081095185334864085897708",
            "length": 674
        },
        "id": "CVE-2026-72660-dc0a4f96",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94",
        "target": {
            "file": "server/src/main/java/org/elasticsearch/search/fetch/subphase/highlight/HighlightBuilder.java",
            "function": "build"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "50460798663850937323875144151113267593",
            "length": 3586
        },
        "id": "CVE-2026-72660-e5c86fee",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94",
        "target": {
            "file": "server/src/test/java/org/elasticsearch/search/fetch/subphase/highlight/HighlightBuilderTests.java",
            "function": "testBuildSearchContextHighlight"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "250502453778712768962053518703255093608",
                "293745187741608286289486472330502044902",
                "92285933861987769382932879499624280339",
                "48848052402887098574079705828368727963",
                "180954780310110417851376237840132855867",
                "265701660666103015958674140349152633739",
                "219483656979539974598819100907886798376"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-72660-f6f0ec86",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94",
        "target": {
            "file": "server/src/main/java/org/elasticsearch/search/fetch/subphase/highlight/PlainHighlighter.java"
        }
    }
]
vanir_signatures_modified
"2026-09-04T08:06:33Z"

Git / github.com/elastic/kibana

Affected ranges

Type
GIT
Repo
https://github.com/elastic/kibana
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "8.0.0"
        },
        {
            "fixed": "8.19.20"
        },
        {
            "introduced": "9.0.0"
        },
        {
            "fixed": "9.3.8"
        },
        {
            "introduced": "9.4.0"
        },
        {
            "fixed": "9.4.5"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

v9.*
v9.4.0
v9.4.1
v9.4.2
v9.4.3
v9.4.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72660.json"